CVE ID | CVE-2013-1084 |
CVSS SCORE | 7.8, AV:N/AC:L/Au:N/C:C/I:N/A:N |
AFFECTED VENDORS |
Novell |
AFFECTED PRODUCTS |
Zenworks |
VULNERABILITY DETAILS |
The specific flaw exists within the unmaninv web service. The issue lies in the failure to user-supplied sanitize input when returning the contents of a file. An attacker can leverage this vulnerability to retrieve credentials which can then be leveraged to execute code under the context of SYSTEM. |
ADDITIONAL DETAILS |
Novell has issued an update to correct this vulnerability. More details can be found at:
http://www.novell.com/support/kb/doc.php?id=7012760 |
DISCLOSURE TIMELINE |
|
CREDIT | Brett Gervasoni |